Category: Insights

  • What It Actually Looks Like to Run a Local LLM at Your Firm

    Over the past year, a growing number of the advisers and fund managers we work with have asked the same question: “Can we run an AI model in-house, so client data never leaves the building?” The answer is yes — and the technology side is more approachable than most firms expect. One quiet desktop machine […]

  • The Camera on Your Analyst’s Face: Why Smart Glasses Have No Place Near Client Data

    Camera-equipped glasses that look like ordinary Ray-Bans now sit at your workstations, recording screens, credentials, and conversations to a consumer cloud you do not control. Why it is a foreseeable risk under Reg S-P and Rule 206(4)-7 — and the one-paragraph prohibition that closes the gap.

  • Employees From Hell: What Disgruntled Insiders Actually Do, and How to Survive It

    The insider threat at a financial firm is not usually a spy. Six attack patterns from the adversary point of view — grounded in the CISA framework and mapped to the rules an examiner will hold you to.

  • Deploying Microsoft 365 as an SEC-Defensible Compliance Platform

    Most RIAs already own Microsoft 365. Far fewer have configured it to do the one thing the SEC now expects it to do: enforce, evidence, and retain the safeguards your written policies promise. The gap between “we have M365” and “we can demonstrate the safeguards rule to an examiner” is almost entirely a deployment problem […]

  • Deploying Google Workspace as an SEC-Defensible Compliance Platform

    Google Workspace is a capable compliance platform for an RIA — but only at the right edition, and only when the security controls that ship switched off are deliberately switched on. The single most expensive mistake advisers make here is assuming a Business-tier plan is enough. It is not: the controls the safeguards rule effectively […]

  • KerberRose Wealth Management Breach Post Mortem: One Inbox, 27,000 People

    One compromised employee mailbox at a wealth management firm reached a backup holding 27,076 clients’ Social Security and bank details. A breach teardown — and what amended Reg S-P now expects on identity, backup segmentation, and the 30-day notice clock.

  • The Attack That Doesn’t Need Your Password

    A subscription phishing kit (FBI Alert I-052126-PSA) hijacks Microsoft 365 OAuth tokens with no password and no MFA prompt. Why it is a Reg S-P and 206(4)-7 problem, and the Conditional Access change to make this week.

  • Is a Remote CISO for You?

    A five-sign self-assessment for RIA compliance officers — when a fractional Remote CISO closes the cybersecurity accountability gap the amended Reg S-P now assumes, at a fraction of a full-time hire.

  • A Model Was Pulled Overnight. Was Your Firm Running On It?

    On June 12, 2026, a US government directive forced two AI models offline for every customer with no notice and no restoration date. For any firm that had built a workflow on one of them, the lesson is not that a model disappeared. The lesson is that AI governance has to operate in real time.

  • The Reg S-P Deadline Just Passed for Small Firms. Here’s What Examiners Ask For First.

    The June 3 compliance date for the amended Regulation S-P has passed for smaller firms. The five documents an examiner will request first — and the 30-day clock most incident response plans still don’t mention.